forbidden
HTTP status: 403
What happened
The credential is valid but does not allow this action. An API key may lack the required scope; identity endpoints require a dashboard token. Dashboard requests need a current membership in the selected organization, and viewers have read-only access. Test mode cannot create live keys. A test key cannot resend a live email.
How to fix
Create a key with the needed scope. Scope cannot be edited after creation; revoke the key and
create another. full reaches authenticated routes except identity endpoints. sending reaches
only POST /emails and POST /emails/batch. A stored domain scope reaches those same two
routes and cannot be created. read_only reaches only GET /usage.
For dashboard access, call GET /me to provision the user, then select a current membership with
Sendtier-Tenant. Omission selects the sole membership; remove a stale header before refreshing
GET /me. The organization members path must match the selected tenant. Request an appropriate
role for writes, and create test keys when using Sendtier-Mode: test.
Source: docs/errors/forbidden.md.